Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2775▲ 14 respecto a la semana anterior
Críticas / altas1290▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1625 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory." | |
| Modificada | Alta (7.5) | 3.1% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.6% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight Commander (mc) 4.5.55 y versiones anteriores, permiten a atacantes remotos causar la Denegación de Servicio (DoS) mediante una sección corrupta de la cabecera. | |
| Modificada | Alta (7.5) | 1.8% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Múltiples desbordamientos de búfer en Midnight Commander (mc) 4.5.55 y versiones anteriores, permiten a atacantes remotos ejecutar acciones de impacto desconocido. | |
| Modificada | Media (5) | 1.4% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles." | |
| Modificada | Alta (10) | 22% | 💥 Exploit | Xmlsoft LibxmlXmlsoft Libxml2Xmlstarlet Command Line XML ToolkitRedhat Fedora Core+2 | 1/3/2005 | 16/6/2026 | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the… | |
| Modificada | Alta (10) | 2.0% | — | Xmlstarlet Command Line XML Toolkit | 31/12/2004 | 16/6/2026 | Multiple buffer overflows in XMLStarlet Command Line XML Toolkit 0.9.3 have unknown impact and attack vectors via (1) xml_elem.c and (2) xml_select.c. | |
| Modificada | Media (6.4) | 1.7% | — | Xmlstarlet Command Line XML Toolkit | 31/12/2004 | 16/6/2026 | Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code. | |
| Modificada | Alta (7.5) | 2.6% | — | HP Storageworks Command View | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the management station in HP StorageWorks Command View XP 1.8B and earlier allows remote attackers to bypass access restrictions. | |
| Modificada | Alta (7.5) | 1.8% | — | Symantec ON Command CCMSymantec ON Icommand | 21/9/2004 | 16/6/2026 | Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (10) | 3.9% | — | Midnight CommanderSGI PropackGentoo LinuxSlackware Linux | 18/8/2004 | 16/6/2026 | Múltiples desbordamientos de búfer en Midnight Commander (mc) anteriores a 4.6.0 pueden permitir a atacantes causar una denegación de servicio o ejecutar código arbitrario. | |
| Modificada | Baja (2.1) | 0.38% | — | Midnight CommanderSGI PropackGentoo LinuxSlackware Linux | 18/8/2004 | 16/6/2026 | Múltiples vulnerabilidades en Midnight Commander (mc) anteriores a 4.6.0, con impacto desconocido, relacionadas con "creación insegura de ficheros y directorios temporales." | |
| Modificada | Media (5) | 2.9% | — | Midnight CommanderSGI PropackGentoo LinuxSlackware Linux | 18/8/2004 | 16/6/2026 | Mútiples vulnerabilidades de cadena de formato en Midnight Commander (mc) anteriores a 4.6.0 pueden permitir a atacantes causar una denegación de servicio o ejecutar código de su elección. | |
| Modificada | Alta (7.5) | 5.1% | — | Midnight Commander | 20/1/2004 | 16/6/2026 | Desbordamiento de búfer basado en la pila en vfs_s_resolve_symlink de vfs/direntry.c en Midnight Commander (mc) 4.6.0 y anteriores, y posiblemente otras versiones permite a atacantes remotos ejecutar código arbitrario durante una conversión de enlaces simbólicos (symlink). | |
| Modificada | Media (5) | 1.9% | — | Http CommanderAI | 31/12/2003 | 16/6/2026 | HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Http Commander | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Applied Watch Technologies Applied Watch Command Center | 15/12/2003 | 16/6/2026 | Applied Watch Command Center permite a atacantes remotos conducir actividades no autorizadas sin autenticación, como Añadir nuevos usuarios a una consola, como se ha demostrado usando appliedsnatch.c, o Añadir reglas IDS espurias a sensores, como se ha demostrado usando addrule.c | |
| Modificada | Media (4.6) | 0.44% | — | Midnight Commander | 12/11/2001 | 16/6/2026 | Buffer overflow in mcedit in Midnight Commander 4.5.1 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted text file. | |
| Modificada | Alta (10) | 4.0% | — | Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+11 | 12/3/2001 | 16/6/2026 | Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. | |
| Modificada | Media (4.6) | 0.34% | — | Midnight Commander | 9/1/2001 | 16/6/2026 | Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed. | |
| Modificada | Media (4.6) | 0.44% | — | Midnight Commander | 9/1/2001 | 16/6/2026 | cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument. | |
| Modificada | Media (4.6) | 0.33% | — | Midnight Commander | 1/8/1999 | 16/6/2026 | FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges. | |
| Modificada | Baja (2.1) | 0.34% | — | Midnight Commander | 1/4/1999 | 16/6/2026 | Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack. |